The WP-Lister Lite for Amazon WordPress plugin before 2.4.4 does not sanitize and escapes a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which can be used against high-privilege users such as admin.
                
            References
                    | Link | Resource | 
|---|---|
| https://wpscan.com/vulnerability/460a01e5-7ce5-4d49-b068-a93ea1fba0e3 | Exploit Third Party Advisory | 
| https://wpscan.com/vulnerability/460a01e5-7ce5-4d49-b068-a93ea1fba0e3 | Exploit Third Party Advisory | 
Configurations
                    History
                    21 Nov 2024, 07:35
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2023-01-02 22:15
Updated : 2025-04-10 19:15
NVD link : CVE-2022-4369
Mitre link : CVE-2022-4369
CVE.ORG link : CVE-2022-4369
JSON object : View
Products Affected
                wplite
- wp-lister_lite_for_amazon
 
CWE
                
                    
                        
                        CWE-79
                        
            Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
